PT-2026-1699 · WordPress · Folders – Unlimited Folders To Organize Media Library Folder
Published
2026-01-08
·
Updated
2026-01-08
·
CVE-2025-12640
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress versions up to and including 3.1.5
Description
The Folders plugin for WordPress is susceptible to unauthorized arbitrary media replacement. This occurs because of a lack of proper object-level authorization checks within the
handle folders file upload() function. Authenticated attackers possessing Author-level access or higher can exploit this to replace any media file within the WordPress Media Library.Recommendations
Versions prior to and including 3.1.5 should be updated to a newer, fixed version of the plugin. As a temporary workaround, consider restricting access to the
handle folders file upload() function for users with Author-level access or below.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Folders – Unlimited Folders To Organize Media Library Folder